Intel

AIKIDO-2024-10158

clickhouse-connect is vulnerable to Exposure of Sensitive System Information

Exposure of Sensitive System Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 1, 2024

15

Low Risk

This Affects:

pythonclickhouse-connect
0.4.0 - 0.7.13
Fixed in 0.7.14
Are you affected? Scan for Free

TL;DR

Affected versions of this package may expose sensitive system information, as the HTTPDriver returns the Clickhouse server IP and port number in the error exception.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

clickhouse-connect is vulnerable to Exposure of Sensitive System Information in versions 0.4.0 - 0.7.13.

How to fix this

Upgrade clickhouse-connect to a patch version.